Executive brief
TorrentPier is an open-source BitTorrent tracker engine. A security vulnerability in how the software handles browser cookies allows an attacker to execute malicious code on the server. This could lead to a complete takeover of the website, theft of user data, or disruption of service.
Technical details
A deserialization of untrusted data vulnerability exists in TorrentPier versions 2.4.3 and earlier. The `get_tracks()` function in `library/includes/functions.php` uses the native PHP `unserialize()` function on the contents of the `bb_t` cookie without proper validation. An unauthenticated remote attacker can exploit this by providing a specially crafted cookie containing a PHP gadget chain (such as Guzzle/FW1). Successful exploitation allows the attacker to perform arbitrary file writes and execute arbitrary PHP code on the underlying server. The issue is addressed in version 2.4.4.
Affected products
- TorrentPier TorrentPier <= 2.4.3
Timeline
- 2024-07-13: disclosed
- 2024-07-15: advisory: GHSA-fg86-4c2r-7wxw published
- 2024-07-15: patched